Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,776
Quick preset (or use dates below)
Clear Filters
Showing 6,161 - 6,180 of 13,900 CVEs
CVE-2026-6564 MEDIUM - 4.3

A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the component Session Handling. The manipulation results in improper authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendo...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6561 MEDIUM - 4.7

A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is...

Published: Apr 19, 2026
Source: NVD
CVE-2026-6559 MEDIUM - 4.3

A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. Th...

Published: Apr 19, 2026
Source: NVD
CVE-2026-0868 MEDIUM - 6.4

The EMC โ€“ Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's calendly shortcode in all versions up to, and including, 4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes ...

Published: Apr 19, 2026
Source: NVD
CVE-2026-40948 MEDIUM - 5.4

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim...

Vendor: Apache Software Foundation
Product: Apache Airflow
Published: Apr 18, 2026
Source: NVD
CVE-2026-2986 MEDIUM - 6.4

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with c...

Published: Apr 18, 2026
Source: NVD
CVE-2026-2505 MEDIUM - 5.4

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_image' shortcode. This is due to the shortcode rendering path passing attacker-controlled class input into a fallback image builder that conc...

Published: Apr 18, 2026
Source: NVD
CVE-2026-0894 MEDIUM - 6.4

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied values consumed from user-cr...

Published: Apr 18, 2026
Source: NVD
CVE-2026-41254 MEDIUM - 4.0

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Vendor: littlecms
Product: little cms color engine
Published: Apr 18, 2026
Source: NVD
CVE-2026-41253 MEDIUM - 6.9

In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initial ace/c+ substring, aka "hypothetical in-band...

Vendor: iTerm2
Product: iTerm2
Published: Apr 18, 2026
Source: NVD
CVE-2026-6048 MEDIUM - 6.4

The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2.1.1 due to insufficient validation of custom attribute names. Specifically, the plugin uses `es...

Published: Apr 18, 2026
Source: NVD
CVE-2026-4801 MEDIUM - 6.4

The Page Builder Gutenberg Blocks โ€“ CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insufficient output escaping of event titles, descriptions, and locations fetched from external iCal feeds in...

Published: Apr 18, 2026
Source: NVD
CVE-2026-40491 MEDIUM - 6.5

gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the filenames of the archive members. This...

Vendor: wkentaro
Product: gdown
Published: Apr 18, 2026
Source: NVD
CVE-2026-40490 MEDIUM - 6.8

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to 3.0.9 and 2.14.5 forward Authorization and Proxy-Authorization headers...

Vendor: AsyncHttpClient
Product: async-http-client
Published: Apr 18, 2026
Source: NVD
CVE-2026-1838 MEDIUM - 6.1

The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary ...

Published: Apr 18, 2026
Source: NVD
CVE-2026-1559 MEDIUM - 6.4

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-lev...

Published: Apr 18, 2026
Source: NVD
CVE-2026-41078 MEDIUM - 5.9

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high...

Vendor: nuget
Product: OpenTelemetry.Exporter.Jaeger
Published: Apr 18, 2026
Source: GitHub
CVE-2026-40881 MEDIUM - 7.5

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB mess...

Vendor: rust
Product: zebrad
Published: Apr 18, 2026
Source: GitHub
CVE-2026-40593 MEDIUM - 4.8

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking charact...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD
CVE-2026-40485 MEDIUM - 5.3

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent users and 401 for valid users with incorrect passwords. An una...

Vendor: ChurchCRM
Product: CRM
Published: Apr 18, 2026
Source: NVD